<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Change timeout session in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/change-timeout-session/m-p/2030257#M438450</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have more one question.&lt;/P&gt;&lt;P&gt;My ACL HitCount is 0, its correct? &lt;/P&gt;&lt;P&gt;If i create a service policy and put in the interface(not in the global) the hitcount begins to appear, why?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Sep 2012 14:45:20 GMT</pubDate>
    <dc:creator>Rafael Mendes</dc:creator>
    <dc:date>2012-09-12T14:45:20Z</dc:date>
    <item>
      <title>Change timeout session</title>
      <link>https://community.cisco.com/t5/network-security/change-timeout-session/m-p/2030255#M438444</link>
      <description>&lt;P&gt;Hello Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I Have a problem here.&lt;/P&gt;&lt;P&gt;We deploy a citrix, and i need set no timeout for especific traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, i create this configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show access-list TimeOutCitrix&lt;/P&gt;&lt;P&gt;access-list TimeOutCitrix; 7 elements&lt;/P&gt;&lt;P&gt;access-list TimeOutCitrix line 1 extended permit ip any host 172.17.2.129 log informational interval 300 (&lt;STRONG&gt;hitcnt=0&lt;/STRONG&gt;) 0x238cd297&lt;/P&gt;&lt;P&gt;access-list TimeOutCitrix line 2 extended permit ip any host 172.17.2.130 log informational interval 300 (&lt;STRONG&gt;hitcnt=0&lt;/STRONG&gt;) 0x80b4c299&lt;/P&gt;&lt;P&gt;access-list TimeOutCitrix line 3 extended permit ip any host 172.17.2.218 log informational interval 300 (&lt;STRONG&gt;hitcnt=0&lt;/STRONG&gt;) 0x726d7587&lt;/P&gt;&lt;P&gt;access-list TimeOutCitrix line 4 extended permit ip any host 172.17.2.224 log informational interval 300 (hitcnt=0) 0x6d9499e1&lt;/P&gt;&lt;P&gt;access-list TimeOutCitrix line 5 extended permit ip any host 172.17.2.226 log informational interval 300 (hitcnt=0) 0x95465853&lt;/P&gt;&lt;P&gt;access-list TimeOutCitrix line 6 extended permit ip any host 172.17.2.227 log informational interval 300 (hitcnt=0) 0x76a9ab24&lt;/P&gt;&lt;P&gt;access-list TimeOutCitrix line 7 extended permit ip any host 172.17.2.232 log informational interval 300 (hitcnt=0) 0x3e7867ad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map TimeOutCitrix&lt;/P&gt;&lt;P&gt; match access-list TimeOutCitrix&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class TimeOutCitrix&lt;/P&gt;&lt;P&gt;&amp;nbsp; set connection timeout tcp 0:00:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But, the session still keep the timeout in 1 hour.&lt;/P&gt;&lt;P&gt;I have this timeout configuration in my firewall(out of the class map).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCP rede_filiais:10.82.16.15/3356 rede_servidores:172.17.2.130/2598,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags UIOB, idle 1s, uptime 54m21s, timeout &lt;STRONG&gt;1h0m&lt;/STRONG&gt;, bytes 154204&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The question is, why this occurs? What i need do for change this traffic timeout? Why the &lt;/P&gt;&lt;P&gt;hitcnt in the acl is 0? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:53:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-timeout-session/m-p/2030255#M438444</guid>
      <dc:creator>Rafael Mendes</dc:creator>
      <dc:date>2019-03-11T23:53:15Z</dc:date>
    </item>
    <item>
      <title>Change timeout session</title>
      <link>https://community.cisco.com/t5/network-security/change-timeout-session/m-p/2030256#M438448</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi rafael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once you implement the policy, you need to do a "Clear conn" and "Clear xlates", so that the new connections would fall under your policy map.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt;Varun Rao &lt;BR /&gt;Security Team, &lt;BR /&gt;Cisco TAC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2012 14:35:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-timeout-session/m-p/2030256#M438448</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-09-12T14:35:03Z</dc:date>
    </item>
    <item>
      <title>Change timeout session</title>
      <link>https://community.cisco.com/t5/network-security/change-timeout-session/m-p/2030257#M438450</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have more one question.&lt;/P&gt;&lt;P&gt;My ACL HitCount is 0, its correct? &lt;/P&gt;&lt;P&gt;If i create a service policy and put in the interface(not in the global) the hitcount begins to appear, why?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2012 14:45:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-timeout-session/m-p/2030257#M438450</guid>
      <dc:creator>Rafael Mendes</dc:creator>
      <dc:date>2012-09-12T14:45:20Z</dc:date>
    </item>
    <item>
      <title>Re: Change timeout session</title>
      <link>https://community.cisco.com/t5/network-security/change-timeout-session/m-p/2030258#M438452</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rafael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would see the hitcounts in the ACL, wat you can verify is the output of :show service-policy" this would tell you if the packets are falling under the policy or not. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Although applying it on the interface would take more preference than the global policy, so if it does not work for the global, you can try changing it to interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt;Varun Rao &lt;BR /&gt;Security Team, &lt;BR /&gt;Cisco TAC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2012 15:15:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-timeout-session/m-p/2030258#M438452</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-09-12T15:15:12Z</dc:date>
    </item>
    <item>
      <title>Change timeout session</title>
      <link>https://community.cisco.com/t5/network-security/change-timeout-session/m-p/2030259#M438454</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok Varun.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now i see the "no timeout" in the output of command "show conn detail".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCP rede_filiais:10.82.16.15/3826 rede_servidores:172.17.2.130/2598,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags UIOB, idle 1s, uptime 32m16s, &lt;STRONG&gt;timeout &lt;/STRONG&gt;-, bytes 154944&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rafael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2012 19:22:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-timeout-session/m-p/2030259#M438454</guid>
      <dc:creator>Rafael Mendes</dc:creator>
      <dc:date>2012-09-12T19:22:25Z</dc:date>
    </item>
  </channel>
</rss>

